About This Architecture
Mastercard PAN-DDA architecture leverages AWS IAM Roles Anywhere to establish certificate-based, passwordless authentication between Mastercard's on-premises PCF data center and AWS Global Platform tenant. MAPDMS service in the PCF data center uses aws_signing_helper with X.509 certificates from Venafi to obtain temporary AWS credentials, validated against Mastercard CA trust anchors via OCSP and CRL endpoints. Data flows securely through AWS Direct Connect private VIF and Transit Gateway to PrivateLink endpoints, with least-privilege IAM roles restricting access to S3, EKS, Lambda, KMS, and Aurora PostgreSQL resources. This architecture demonstrates zero-trust hybrid connectivity, eliminating long-lived credentials and enforcing certificate chain validation at every authentication boundary. Fork this diagram on Diagrams.so to customize trust anchors, endpoint configurations, or regional deployments for your own hybrid PKI-based AWS integrations.